The General Data Protection Regulation (GDPR, German: DSGVO, Datenschutz-Grundverordnung) is a European Union regulation for the protection of personal data. It has applied directly in all EU member states since 25 May 2018 and replaces the former Directive 95/46/EC of 1995.
Core principles of the GDPR
- Lawfulness: Data processing only on the basis of a legal basis (e.g. consent, performance of a contract)
- Purpose limitation: Data may only be used for specified purposes
- Data minimisation: Collect only the data that is actually necessary
- Accuracy: Incorrect data must be corrected or deleted
- Storage limitation: Store data only as long as necessary
- Integrity and confidentiality: Technical and organizational safeguards
Penalties
Violations can result in fines of up to 20 million euros or 4% of worldwide annual turnover.
Relevance for appointment scheduling systems
- Servers located in Germany or the EU
- GDPR-compliant consent declarations in the booking form
- Right to erasure: customers can request the deletion of their data
- Data processing agreement (DPA) with the system provider
- Privacy policy on the booking page